At a Glance
- Tasks: Lead cyber security oversight in aviation, ensuring safety and compliance.
- Company: Join the UK's leading aviation and aerospace regulator.
- Benefits: Competitive salary, hybrid work, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace with a commitment to continuous improvement.
- Why this job: Make a real impact on aviation safety and security while working with experts.
- Qualifications: Experience in cyber security or IT, with strong communication skills.
The predicted salary is between 56667 - 71957 £ per year.
Salary: £56,667 to £71,957 – (dependent on experience)
Contract Type: Permanent – Full-Time
Security Level: SC
Location: Gatwick – Hybrid - min 2 days in the office or industry visits per week.
Visa Restrictions: This position does not offer visa sponsorship
Closing Date: Friday 28th August 2026
Screening Calls: w/c 31st Monday 2026
Interview Date: From w/c Monday 14th September 2026
We are the UK's aviation and aerospace regulator and recognised as a world leader in its field. Our activities are diverse, enabling the aviation industry to meet the highest safety standards, and we pride ourselves on our ability to adapt to the constantly evolving aviation environment.
The Role
Are you an experienced information security professional looking for a new challenge? Or perhaps you're keen to move from an internal consultancy, assurance, or IT audit role into a more outward-facing position where you can influence the future of cyber security in aviation? If so, this could be the opportunity for you.
The CAA Cyber Safety Oversight Team provides cyber security oversight across a range of aviation safety domains, including Aerodromes, Continuing Airworthiness, Air Traffic Management, and Flight Operations. We have built a highly collaborative environment where cyber specialists work alongside aviation experts to develop, implement, and continuously improve proportionate, risk-based oversight approaches.
Alongside our aviation safety responsibilities, the CAA as co-competent authority with the Department for Transport (DfT) for the Network and Information Systems Regulations 2018 (NIS) is responsible for regulatory oversight and post-incident investigations under NIS, delivered through the CAA's Cyber Security Oversight Process for Aviation (CAP1753).
As an Aviation Cyber Oversight Specialist, you will play a pivotal role in delivering the UK Aviation Cyber Security Strategy and the CAA's Cyber Security Oversight Strategy. You will help drive the evolution of our cyber oversight capabilities, ensuring our approach remains proactive, intelligence-led, and aligned with the Regulator's Code, Growth Duty, and CAA Regulatory Principles.
Working at the forefront of aviation cyber security, you will contribute to the development and application of cyber security regulations, standards, and guidance that help maintain the safety, security, and resilience of the UK's aviation sector.
A key part of the role will involve shaping and delivering the CAA's cyber oversight activities. This includes leading and participating in audits and inspections of aviation organisations, assessing the cyber risks associated with systems critical to aviation safety, security and resilience, reviewing cyber security self-assessments and evidence and formulating an expert opinion on an organisation's cyber security posture, monitoring the implementation of corrective actions, and holding organisations accountable for addressing identified deficiencies.
The successful candidate will have a strong background in information technology, operational technology, cyber security, or senior GRC roles, with practical knowledge of information security frameworks and controls, and the ability to evaluate technical documentation and controls implementation.
Strong stakeholder engagement skills are essential. You will be comfortable working with a diverse range of organisations and individuals, from technical specialists and senior leaders to government and industry representatives and will be able to communicate complex concepts clearly and effectively to different audiences.
Core Accountabilities
- To work in collaboration with CAA safety and security colleagues to establish and mobilise an ongoing oversight regime that ensures aviation organisations are meeting cyber security requirements according to their applicable regulations.
- Perform initial and ongoing oversight activities predominantly in aviation safety, but also in aviation security and resilience where appropriate. Activities will include, but not limited to, audits (both onsite and remote), inspections, reviewing evidence and reports, determining the suitability of corrective actions and monitoring progress in completion.
- Confidently communicate areas of non-compliance both with CAA stakeholders and aviation organisations.
- Work with, and guide, accredited third parties in line with the CAA’s Cyber Security Oversight model.
- Represent the CAA Cyber Oversight Team to the wider industry through working groups and events.
- Participate in the development and delivery of aviation cyber security training and guidance.
- Review aviation cyber security risk through threat and vulnerability assessments, communicating effectively to both industry and other CAA capability areas to inform safety and security decision making.
- Contribute towards a culture of continuous improvement in developing cyber security oversight practices, standards, and guidance consistent with the Regulators’ Code, the CAA’s cyber oversight objectives, our safety objectives and aviation security regulations.
About You
Essential:
- The ideal candidate would be someone seeking a new challenge that currently works in a hands-on cyber security, information security or information technology or operations technology capacity.
- Experience in technology systems supporting critical infrastructure or operational environments, is highly desirable.
- Practical experience with security frameworks such as ISO 27001, NIST Cybersecurity Framework, NCSC Cyber Assessment Framework (CAF), or similar industry standards, ideally in an assessment or audit capacity.
- Knowledge of cloud computing and security, industrial control systems (ICS), operational technology (OT), or critical infrastructure, cyber security.
- Professional certifications such as CISSP, CISM, CRISC, Network+, Security+, GICSP, SANS ICS410/301/401, ISO ISA/IEC 62443, ISO27001 lead auditor/implementer, CCSK or equivalent recognised certifications.
- You'll be capable of translating complex technical concepts for diverse stakeholder audiences, from technical teams to senior management and other government departments and CAA colleagues.
- You’re a great team player with a forward-thinking approach, recognising that cyber security in UK civil aviation is a rapidly evolving area, meaning that there are many technical and regulatory uncertainties.
- You will possess strong analytical and communication skills with the ability to present technical oversight reports clearly and concisely, both in writing and verbally.
- Strong interpersonal skills and the ability to build and maintain relationships and resolve conflict calmly.
- Since the role will require travel to visit regulated entities, suitable candidates will hold a clean UK driver's license and not be averse to travel. This may also necessitate occasional overnight stays.
Additional Information
For many appointments within the CAA, these roles require access to operationally sensitive infrastructure and/or Nationally Protected information. For these roles the post holders must undergo National Security Vetting and achieve the appropriate level of clearance.
SC - To be vetted we will usually expect a reasonable period of residency in the UK so that meaningful checks can be undertaken. For this role this will need to be 5 years.
If you do not meet these requirements, we may not be able to accept your application.
The CAA values high ethical standards and personal integrity among employees. If invited for interview you will be asked to complete a declaration of interest.
Relocation & Property
The CAA will be relocating from Aviation House (Our Gatwick Office) to new premises in a few years’ time. Our move is driven by strategic, operational and environmental considerations.
We will be moving to a new local home, up to a 15-mile radius of Aviation House, to minimise disruption for our valued colleagues and customers.
We are now working with colleagues and visitors to understand what we need in our new office, before we start our property search. We will sell Aviation House and land, vacate the site and move to new premises, but we do not expect to move before 2028.
Inclusive Recruitment
We are committed to building a diverse and inclusive workforce and welcome applications from all backgrounds. As a Disability Confident employer, candidates who meet the minimum requirements will be guaranteed an interview. Find out more about the Disability Confident Scheme. If you require any adjustments during the recruitment process, please let us know.
Use of Artificial Intelligence by candidates in the CAA recruitment process
We recognise that many of our candidates find Artificial Intelligence to be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be rejected on that basis.
Working With Us
Explore What We Offer section on our careers website to find out about our benefits and how we support work-life balance.
Our Values: Do The Right Thing, Never Stop Learning, Build Collaborative Relationships, Respect Everyone.
We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible. No recruitment agencies please.
Cyber Security Oversight Specialist in London employer: UK Civil Aviation Authority
As a leading regulator in the UK's aviation and aerospace sector, we offer a dynamic work environment that fosters collaboration and innovation. Our commitment to employee growth is evident through continuous learning opportunities and a supportive culture that values integrity and inclusivity. Located in Gatwick, our office provides a unique chance to engage with diverse stakeholders while contributing to the safety and advancement of the aviation industry.
Contact Details:
UK Civil Aviation Authority Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Oversight Specialist in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including UK Civil Aviation Authority, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through UK Civil Aviation Authority
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at UK Civil Aviation Authority. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Security Oversight Specialist in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at UK Civil Aviation Authority insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to UK Civil Aviation Authority that you’re committed to staying ahead in the game.
How to prepare for a job interview at UK Civil Aviation Authority
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at UK Civil Aviation Authority to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at UK Civil Aviation Authority.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.